China is reportedly planning to develop its own national post-quantum cryptography standards within the next three years, even as most of the world has already begun transitioning to the standards finalized by the US in 2024.

Post-quantum cryptography deals with algorithms that can protect data from the threats posed by future quantum computers, which are expected to be able to decrypt data (encrypted with older algorithms) much faster than conventional computers. Governments are pushing for their widespread adoption today to reduce the scope of attacks.
Chinese experts in post-quantum cryptography have focused on a different type of algorithm than those favored elsewhere, said Wang Xiaoyun, a professor at the Institute for Advanced Study at Tsinghua University.
See also: Quantum Computing vs Cryptography
China wants its own post-quantum cryptography standards
The algorithms could be ready within three years, and the finance and energy will be priorities for the transition, given the sensitivity of their data. China is not simply adopting what the rest of the world is implementing, Wang said, because its researchers have focused on unstructured algorithms, which they consider more powerful than the algebraic grid designs used elsewhere.
The latter “involve some degree of security degradation,” while unstructured algorithms “essentially do not have this problem,” according to the Reuters report.
The US, UK, EU and Australia have aligned themselves with three standards published by the US National Institute of Standards and Technology (NIST): ML-KEM, ML-DSA and SLH-DSA — and have set transition deadlines between 2030 and 2035.
The UK's National Cyber Security Centre has advised organisations to identify vulnerable systems by 2028 and complete full transition by 2035.

Meanwhile, the China Institute of Commercial Cryptography Standards launched a global call for post-quantum algorithm proposals in February 2025. No algorithm choices have been announced.
If Wang's three-year estimate holds, China's standards will arrive about five years after those of NIST.
Serious concern
Wang is no coincidence. She is the cryptographer who demonstrated collision attacks against MD5 and SHA-1 in 2004 and 2005, two hash functions that the wider community considered secure. Her work led to their gradual removal from most major software systems.
See also: Lawsuit against Meta: WhatsApp encryption is a lie
So her views matter: “When she raises questions about algebraic lattices, it’s not some nationalistic talking point or fringe theory,” said Dr. Arindam Sarkar, head of computer and electronics science at Ramakrishna Mission Vidyamandira. “It’s coming from someone who has a history of finding vulnerabilities that everyone else has overlooked.” Sarkar explained the underlying concern. “Structured lattices have patterns that could potentially be exploited in the future,” he said. “It’s like having a lock that follows a predictable pattern versus one that is intentionally irregular. A pattern lock might be perfectly secure today, but if someone discovers the underlying pattern twenty years from now, there will be problems.”
NIST itself has guarded against the possibility of lattice weaknesses: In March 2025, it selected HQC, a code-based algorithm based on different mathematics (as a fallback fourth standard). Dustin Moody, a mathematician who leads NIST’s Post-Quantum Cryptography project, said at the time: “We want to have a fallback standard that is based on a different mathematical approach than ML-KEM. As we advance our understanding of future quantum computers and adapt to emerging cryptanalysis techniques, it is essential to have an alternative in case ML-KEM proves vulnerable.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Security, dominance or both
China's preference for domestic encryption standards is not new. It has previously developed its own classical encryption algorithms and enforced their use domestically, requiring foreign technology companies operating in China to support them alongside international standards.
Sarkar said the motivations behind China’s push for unstructured grids are not purely technical. “Every major tech power wants some degree of cryptographic independence,” he said. “The security arguments are genuine, but so is the desire to control your own destiny. That doesn’t invalidate China’s approach. It makes them a legitimate player in a world where cryptography is becoming increasingly strategic.”

Security agencies and financial regulators estimate that government agencies are already intercepting and storing encrypted data today, with the aim of decrypting it once capable quantum computers.
The National Endowment for Democracy has reported that China is already engaged in such activities. NIST has warned that sensitive data “retains its value for many years,” making timely transition critical.
“The five-year gap creates a really difficult position for anyone operating in China,” Sarkar said. “Are you going to implement NIST algorithms now to protect against immediate threats, knowing that they might not meet China’s future compliance requirements? Or are you going to wait for Chinese standards and leave that window open?”
See also: Why comparing Apple and Microsoft on the subject of encryption is not fair
Do not wait
Sarah Almond, principal analyst at Gartner, said the compliance challenge extends beyond China. “Many regions worldwide are adopting NIST’s PQC standards,” she said. “China is one region, among others, that is starting its own PQC standardization initiatives. But it’s not new for some regions to adopt their own cryptographic standards.”
Enterprises assessing vendors’ readiness for quantum technology should ask whether support for regional standards will be provided in core products, as a paid feature or not at all. Sarkar advised against waiting. “Start hybrid deployments immediately,” he said. “Combine NIST-approved existing classical cryptography your. Build systems that can swap algorithms as requirements become clearer. The worst possible position is to be frozen, doing nothing, while the clock keeps ticking.”
